25 Sources
[1]
The rise of Moltbook suggests viral AI prompts may be the next big security threat
On November 2, 1988, graduate student Robert Morris released a self-replicating program into the early Internet. Within 24 hours, the Morris worm had infected roughly 10 percent of all connected computers, crashing systems at Harvard, Stanford, NASA, and Lawrence Livermore National Laboratory. The
[2]
OpenClaw is a security nightmare - 5 red flags you shouldn't ignore (before it's too late)
If you plan on trying out Moltbot for yourself, be aware of these security issues. Clawdbot, which was first rebranded as Moltbot following an IP nudge from Anthropic, and then to OpenClaw this weekend, has been at the center of a viral whirlwind to end January -- but there are security
[3]
DIY AI bot farm OpenClaw is a security 'dumpster fire'
Your own personal Jarvis. A bot to hear your prayers. A bot that cares. Just not about keeping you safe OpenClaw, the AI-powered personal assistant users interact with via messaging apps and sometimes entrust with their credentials to various online services, has prompted a wave of malware and is
[4]
Researchers Find 341 Malicious ClawHub Skills Stealing Data from OpenClaw Users
A security audit of 2,857 skills on ClawHub has found 341 malicious skills across multiple campaigns, according to new findings from Koi Security, exposing users to new supply chain risks. ClawHub is a marketplace designed to make it easy for OpenClaw users to find and install third-party skills.
[5]
Viral Moltbot AI assistant raises concerns over data security
Security researchers are warning of insecure deployments in enterprise environments of the Moltbot (formerly Clawdbot) AI assistant, which can lead to leaking API keys, OAuth tokens, conversation history, and credentials. Moltbot is an open-source personal AI assistant with deep system integration
[6]
AI assistant Moltbot is going viral - but is it safe to use?
Follow ZDNET: Add us as a preferred source on Google. ZDNET's key takeaways * Moltbot has been garnering lots of attention in the AI space. * The tool's developer describes it as "the AI that actually does things." * It's best to run Moltbot in a silo, like the 2024 M4 Mac Mini. One of the
[7]
OpenClaw ecosystem still suffering severe security issues
Researchers disclose rapid exploit chain that let attackers run code via a single malicious web page Security issues continue to pervade the OpenClaw ecosystem, formerly known as ClawdBot then Moltbot, as multiple projects patch bot takeover and remote code execution (RCE) exploits. The initial
[8]
Everyone Really Needs to Pump the Brakes on That Viral Moltbot AI Agent
A new AI chatbot/agent is looking to dethrone the corporate overlords of Google, Microsoft, and the Too Big To Fail startups like OpenAI and Anthropic -- but being an early adopter comes with some real risks. Moltbot (previously Clawdbot, but it underwent a name change after some "polite" pressure
[9]
Personal AI Agents like OpenClaw Are a Security Nightmare
This blog is written in collaboration by Amy Chang, Vineeth Sai Narajala, and Idan Habler Over the past few weeks, Clawdbot (then renamed Moltbot, later renamed OpenClaw) has achieved virality as an open source, self-hosted personal AI assistant agent that runs locally and executes actions on the
[10]
Silicon Valley's Favorite New AI Agent Has Serious Security Flaws
The AI agent once called ClawdBot is enchanting tech elites, but its security vulnerabilities highlight systemic problems with AI. A hacker demonstrated that the viral new AI agent Moltbot (formally Clawdbot) is easy to hack via a backdoor in an attached support shop. Clawdbot has become a Silicon
[11]
Moltbook shows rapid demand for AI agents. The security world isn't ready.
Why it matters: Security teams, corporate leaders and government officials are far from ready for a reality where agents have real autonomy inside their systems. Driving the news: Since Thursday, 1.5 million AI agents have joined Moltbook, a social network designed just for agents built from an
[12]
OpenClaw proves agentic AI works. It also proves your security model doesn't. 180,000 developers just made that your problem.
OpenClaw, the open-source AI assistant formerly known as Clawdbot and then Moltbot, crossed 180,000 GitHub stars and drew 2 million visitors in a single week, according to creator Peter Steinberger. Security researchers scanning the internet found over 1,800 exposed instances leaking API keys,
[13]
Fake Moltbot AI assistant just spreads malware - so AI fans, watch out for scams
Attack quickly detected and stopped, but Moltbot's site flagged dangerous Hackers have hijacked the good name of Moltbot and used it to deliver malware to countless unsuspecting users - but fortunately, the attack was quickly spotted and stopped. Moltbot is an open source personal AI assistant
[14]
Personal AI Agents like Moltbot Are a Security Nightmare
This blog is written in collaboration by Amy Chang, Vineeth Sai Narajala, and Idan Habler Over the past few weeks, Clawdbot (now renamed Moltbot) has achieved virality as an open source, self-hosted personal AI assistant agent that runs locally and executes actions on the user's behalf. The bot's
[15]
Researchers say viral AI social network Moltbook is a 'live demo' of how the new internet could fail | Fortune
Security researchers say OpenClaw -- the AI agent software (previously Clawdbot/Moltbot) that powers many bots on Moltbook -- is already a target for malware. A report from OpenSourceMalware found 14 fake "skills" uploaded to its ClawHub site in days, pretending to be crypto trading tools but
[16]
The viral Clawdbot AI agent can do a lot for you, but security experts warn of risks
How an AI assistant built for automation can become an attacker's shortcut Clawdbot, the AI agent that took the tech world by surprise, became one of the fastest-climbing projects on GitHub because it promised something unusual. Instead of just chatting, Clawdbot can interact with your files,
[17]
Clawdbot Chaos: A Forced Rebrand, Crypto Scam and 24-Hour Meltdown
Security researchers uncover exposed Clawdbot instances and credential risks. A few days ago, Clawdbot was one of GitHub's hottest open-source projects, boasting more than 80,000 stars. It's an impressive piece of engineering that lets you run an AI assistant locally with full system access
[18]
Moltbot (Formerly Clawdbot) Already Has a Malware Problem
The extension allows bad actors to connect to your device via a remote desktop program, so they can take over the device. Moltbot (formerly known as Clawdbot) is the most viral AI product I've seen in a while. The personal AI assistant runs locally and connects via a chat app, like WhatsApp or
[19]
Silicon Valley's latest AI agent obsession is riddled with security risks
Why it matters: This is just the beginning, and AI adopters are already hastily picking convenience over digital security. Driving the news: All week, tech enthusiasts have been flocking to an open-source AI agent called Moltbot -- previously known as Clawdbot -- that runs on a computer and
[20]
Infostealers added Clawdbot to their target lists before most security teams knew it was running
Clawdbot's MCP implementation has no mandatory authentication, allows prompt injection, and grants shell access by design. Monday's VentureBeat article documented these architectural flaws. By Wednesday, security researchers had validated all three attack surfaces and found new ones. Commodity
[21]
Clawdbot AI Flaw Exposes API Keys And Private User Data
Cybersecurity researchers have raised red flags about a new artificial intelligence personal assistant called Clawdbot, warning it could inadvertently expose personal data and API keys to the public. On Tuesday, Blockchain security firm SlowMist said a Clawdbot "gateway exposure" has been
[22]
The Tech World Loves This Powerful AI Agent -- But It's Also 'a Security Nightmare'
You can be forgiven if you haven't heard of Moltbot, an AI agent formerly known as Clawdbot. The open-source AI agent has taken the AI developer world by storm over the past week. Some commenters are saying the lobster-themed agent is a godsend for solopreneurs -- but be warned, it's a tool for
[23]
Agent-Only Social Media Is Here | PYMNTS.com
By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions. Within days, the platform had registered more than over 1.5 million AI agent
[24]
Crypto Market News: Clawdbot Security Crisis Exposes Open Servers and Crypto Scams
Unsecured AI Agent Deployments Trigger Server Takeovers and Token Imitation An explosive rise in Clawdbot adoption has exposed thousands of internet-facing servers. It has triggered urgent warnings from about unauthenticated access and full system compromise risks. Security scans this week
[25]
Beware of using Clawdbot or Moltbot, warn security researchers: Here's why
The promise of a "personal AI agent" that can manage your life - booking dinner reservations, screening calls, and sorting your inbox - is finally moving from science fiction to reality. But as the open-source tool Moltbot (recently rebranded from Clawdbot) goes viral among tech enthusiasts, a
Share
Copy Link
OpenClaw, the open-source AI assistant that exploded to 150,000 GitHub stars in months, has become a security nightmare. Researchers discovered 341 malicious skills on ClawHub stealing credentials, while exposed instances leak API keys and OAuth tokens. The platform's 770,000 AI agents on Moltbook face prompt injection attacks that could herald a new era of AI worms.
The rapid ascent of OpenClaw, an open-source AI assistant created by Austrian developer Peter Steinberger, has exposed critical vulnerabilities that security researchers are calling an "absolute nightmare" and a "security dumpster fire."
1
Since launching in November 2025, the project has accumulated over 150,000 GitHub stars, making it one of the fastest-growing AI open-source projects on the platform.2
But this breakneck popularity has created an ecosystem ripe for exploitation, with researchers identifying hundreds of malicious skills and exposed instances leaking sensitive data across the internet.
Source: Inc.
Unlike cloud-based chatbots, OpenClaw runs locally on users' devices with deep system integration, connecting to messaging platforms like WhatsApp, Telegram, and Slack while performing autonomous tasks at regular intervals.
2
The AI assistant harnesses the power of Anthropic's Claude and OpenAI's ChatGPT models, but its organizing code runs on individual computers, granting it access to email, messages, and file systems. This architecture requires users to grant system-level controls and account permissions, creating what Cisco researchers describe as an extended attack surface where threat actors can craft malicious prompts that cause unintended behavior.2
A security audit conducted by Koi Security revealed 341 malicious skills across multiple campaigns on ClawHub, the marketplace designed for OpenClaw users to find and install third-party extensions.
4
Of these, 335 skills use fake prerequisites to install Atomic Stealer (AMOS), a commodity macOS stealer available for $500-1000 per month that harvests data from infected hosts. The malicious skills masquerade as legitimate tools with professional-looking documentation, instructing users to download trojan files on Windows or execute obfuscated shell commands on macOS that fetch next-stage payloads from attacker-controlled infrastructure.
Source: 404 Media
The problem stems from ClawHub being open by default, allowing anyone with a GitHub account at least one week old to upload skills. Security researcher Jamieson O'Reilly demonstrated how trivial it would be to backdoor a skill, publishing a minimal "ping" payload and artificially inflating its download count to become the most popular asset.
5
Within eight hours, 16 developers in seven countries had downloaded the artificially promoted skill, illustrating the ease of supply-chain attacks against the platform.4
Pentester Jamieson O'Reilly discovered hundreds of OpenClaw Control admin interfaces exposed online due to reverse proxy misconfiguration.
5
Because OpenClaw auto-approves "local" connections, deployments behind reverse proxies often treat all internet traffic as trusted, allowing unauthenticated access to sensitive data. O'Reilly found instances with no authentication protection whatsoever, leaking Anthropic API keys, Telegram bot tokens, Slack OAuth credentials, signing secrets, and complete conversation histories.2

Source: VentureBeat
OpenClaw has already been reported to have leaked plaintext API keys and credentials, which can be stolen by threat actors via prompt injection or unsecured endpoints.
2
The lack of sandboxing by default means the AI assistant has the same complete access to data as the user, with credentials stored in plaintext under ~/.clawdbot/.5
Token Security claims that 22 percent of its enterprise customers have employees actively using OpenClaw, likely without IT approval, raising concerns about corporate data leakage via AI-mediated access.5
Related Stories
Researchers at Simula Research Laboratory identified 506 posts on Moltbook—the simulated social network where OpenClaw agents interact—containing hidden prompt injection attacks, representing 2.6 percent of sampled content.
1
Moltbook now hosts over 770,000 registered AI agents controlled by roughly 17,000 human accounts, creating the first large-scale network of semi-autonomous AI agents that can communicate through major communication apps.1
Prompt injection attacks require an AI assistant to read and execute malicious instructions hidden in source web material or URLs, potentially causing the agent to leak sensitive data, send information to attacker-controlled servers, or execute tasks with the privileges it has been granted.
2
Security researchers have predicted the rise of self-replicating adversarial prompts among networks of AI agents—what might be called "prompt worms" or "prompt viruses"—that spread through networks of communicating AI agents similar to how traditional worms spread through computer networks.1
Palo Alto Networks warned that OpenClaw represents what British programmer Simon Willison describes as a "lethal trifecta" that renders AI agents vulnerable by design due to their access to private data, exposure to untrusted content, and the ability to communicate externally.
4
With persistent memory, attacks are no longer just point-in-time exploits but become stateful, delayed-execution attacks where malicious payloads can be fragmented, written into long-term agent memory, and later assembled into executable instructions.4
Beyond security vulnerabilities, OpenClaw users are discovering unexpected financial burdens. Benjamin De Kraker, an AI specialist at The Naval Welding Institute, reported burning through $20 worth of Anthropic API tokens while he slept, simply by checking the time.
3
A "heartbeat" cron job set up to issue a reminder checked the time every 30 minutes, sending around 120,000 tokens of context to Claude Opus 4.5.2 model at approximately $0.75 per check, amounting to nearly $20 for 25 checks. The potential cost to run reminders over a month would be about $750.3
In the past three days alone, the project has issued three high-impact security advisories: one one-click remote code execution vulnerability and two command injection vulnerabilities.
3
Creator Peter Steinberger has since rolled out a reporting feature allowing signed-in users to flag skills, with skills receiving more than three unique reports being auto-hidden by default.4
However, deploying OpenClaw safely requires isolating the AI instance in a virtual machine and configuring firewall rules for internet access, rather than running it directly on the host OS with root access.5
Summarized by
Navi
[3]
[5]
27 Jan 2026•Technology

30 Jan 2026•Technology

04 Feb 2026•Technology

1
Technology

2
Science and Research

3
Technology
